2026-09-03T0410Z-intel
One pipeline fire, in full · intel run of 2026-09-03 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations, and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-09-03/2026-09-03T0410Z-intel.md.
Run telemetry
- Items returned
- 4
- Duration
- 8m 38s
- Tool calls
- 0 WebFetch8 WebSearch28 bridge
- Cited sources
- 2 of 23 in slice
- Items returned
- 1
- Duration
- 9m 55s
- Tool calls
- 17 WebFetch17 WebSearch11 bridge
- Cited sources
- 1 of 27 in slice
- Items returned
- 9
- Duration
- 24m 33s
- Tool calls
- 18 WebFetch13 WebSearch57 bridge
- Cited sources
- 5 of 22 in slice
- Items returned
- 1
- Duration
- 6m 15s
- Tool calls
- 6 WebFetch8 WebSearch18 bridge
- Cited sources
- 1 of 11 in slice
- Items returned
- 0
- Duration
- 2m 05s
- Tool calls
- 0 WebFetch4 WebSearch3 bridge
- Cited sources
- 4 of 5 in slice
- Items returned
- 0
- Duration
- 16m 17s
- Tool calls
- 0 WebFetch3 WebSearch27 bridge
- Cited sources
- 1 of 1 in slice
Verification
Deep dive
2026-09-03/gambling-goblin-earth-berberoka-gov-apache-seo-fraud
Entries this run published (9) and updated (2)
- Finland's NCSC-FI publishes an operational manufacturer checklist for the EU Cyber Resilience Act's 24h/72h/14-day/1-month reporting clock, two weeks before the 11 September 2026 go-live policy notable update
- CVE-2026-82078 / CVE-2026-81578, PaperCut NG/MF: an Apache Tapestry request-routing confusion chains an unauthenticated config rewrite to arbitrary code execution, exploited before a patch existed vulnerability critical update
- CVE-2026-59822, BerriAI LiteLLM: a failed key check on the MCP gateway substitutes an empty auth object instead of rejecting the request, so a fabricated Bearer token opens a live MCP session vulnerability high
- CVE-2026-83548 / CVE-2026-83549 (SonicWall SMA1000: a pre-auth SSRF through an undocumented Work Place access path chains into post-auth command injection in the Management Console) both under active exploitation vulnerability high
- CVE-2026-9586, Sangoma Switchvox: an unauthenticated XML phone-notification endpoint reaches PostgreSQL COPY TO PROGRAM, and honeypots caught exploitation nearly seven weeks after the patch shipped vulnerability high
- GitSpawn (CVE-2026-72718); a hostile repository's own git config runs arbitrary commands during AI coding agents' routine startup housekeeping, before any trust prompt vulnerability notable
- Gambling Goblin (Earth Berberoka overlap): a Chinese-speaking cluster compiles malicious Apache modules on compromised Brazilian .gov.br servers, borrowing their search-engine trust for a global gambling-SEO fraud network threat notable
- MoiClient: an invoice-themed backdoor chains an RPC-based UAC bypass with a vulnerable Lenovo PC Manager driver to kill security products and steal browser credentials threat notable
- Kimsuky's seafood-invoice LNK campaign abuses Backblaze B2 cloud storage as C2 and exfiltration infrastructure, keyed by victim BIOS serial number threat notable
- CVE-2026-0768, Langflow: a code-injection RCE patched since January sees renewed mass exploitation, harvesting AWS and OpenAI credentials from environment variables vulnerability high
- A Teams helpdesk-impersonation campaign installs a Node.js implant (Microsoft detection name: EtherRatz) via a silent MSI, then pivots over WinRM straight to domain controllers and certificate authorities threat high
Sources changed (this run)
Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.
2 notes appended; consecutive_fetch_failures +1.
| Source | Change | From → To | Reason |
|---|---|---|---|
| inside-it-ch | notes appended; consecutive_fetch_failures +1 | 3 consecutive 403/paywall failures → · | new failure mode (whole-host 429) observed this run |
| ssd-disclosure | notes appended; consecutive_fetch_failures +1 | 1 → · | anti-bot interstitial recurred on the listing page this run |
Coverage gaps (this run)
Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)
| Source (uncovered) | URL tried | Method chain | Status / class | What the agent did instead |
|---|---|---|---|---|
| inside-it-ch | https://www.inside-it.ch/ | bridge:rss → bridge:extract → bridge:jina → webfetch | 429 rate-limited whole-host HTTP 429 on every transport attempted (direct bridge, extract/jina, plain WebFetch) | none, 403/429-class transport block never demotes; logged as a coverage gap, backlog row updated |
| ssd-disclosure | https://ssd-disclosure.com/ | direct → jina | 202 anti-bot-interstitial Cloudflare/SiteGround-style robot-challenge interstitial on the listing page, both direct bridge and jina fallback; this run's own source_health.py sweep separa | none, recurring anti-bot block, not demoted; sources.json note appended |
Verification findings · all iterations
Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.
Iteration #1 NEEDS_FIXES · 9 findings (truth=6, editorial=3, advisory=0) · Claude Sonnet 5 · 10m 02s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F4 hallucinated-fact | · | affected-version baseline attributed to SecurityWeek/BleepingComputer was actually reused, uncited, from this store's own 2026-07-14 SonicWall entry's fixed-version figure | affected field reworded to 'all releases prior to the fixed hotfixes below' (fully supported by cited sources); reliability downgraded A to B for consistency wi | |
| F4 hallucinated-fact | · | body said plural 'federal ministries'; cited sources state a singular ministry plus a separate national public agency category, dropped | corrected to 'a federal ministry, a national public agency' matching cited source wording | |
| F4 hallucinated-fact | · | techniques[] carried T1685 (Disable/Modify Tools) with no corresponding behavior described in the body | added the source-supported detail (oRAT's setenforce 0 SELinux-disable during its setup routine) to the oRAT body passage | |
| F4 hallucinated-fact | · | update record's fields[] omitted evidence and sourcing_note, both changed per git diff | fields[] corrected to include evidence and sourcing_note | |
| F5 missing-citation | · | CVE-2026-0770 CWE/parameter-distinctness clause carried no inline citation | added a ZDI-26-036 citation (fetched by the Phase 2 CVE-verify spot-check) and a matching sources[] record | |
| F5 missing-citation | · | 'SRP will be available in English only at launch' carried no inline citation | added the already-cited ENISA SRP FAQ citation at that sentence | |
| F17 ? | · | (low confidence) reliability A inconsistent with the entry's own admitted B-tier dependency | covered by the affected-field fix above (reliability downgraded to B) | |
| F17 ? | · | (low confidence) update record's fields[] named classification though the block's stored values did not change | removed classification from fields[] | |
| F15 ? | · | (low confidence) EtherRAT/EtherRatz overlap discussed in prose but not reflected on the registry record | added EtherRatz as a registry alias on malware:etherrat with a note that Microsoft's own reporting never uses the name EtherRAT, an alias for the overlap, not a |
Iteration #2 NEEDS_FIXES · 10 findings (truth=7, editorial=3, advisory=0) · Claude Sonnet 5 · 11m 39s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F4 hallucinated-fact | · | iteration-1 fix removed the fabricated version-ceiling numbers from frontmatter cves[].affected but left the identical figures, cited to SecurityWeek, in the body prose | body reworded to 'any release before the fixed hotfixes below', matching the frontmatter fix | |
| F14 ? | · | summary said 'Defender, Kaspersky, Bitdefender and five other security products'; body's own full list totals 7, meaning 4 others, not 5 | corrected to 'four other security products' | |
| F5 missing-citation | · | 'Manifold states the underlying pattern is not limited to the named agents...' carried no citation | added a heise Security citation (heise directly quotes Manifold making this statement) | |
| F15 ? | · | Microsoft's own cited detection table names Trojan:JS/SynkLoader.SA and Trojan:Win32/SynkLoader.SA for the same MSI/loader stage the entry describes; the store already tracks malware:synkloader from a | added malware:synkloader to entities[], added the 2026-08-24 SynkLoader entry to references[], added a body sentence naming the detection-level overlap on the l | |
| F4 hallucinated-fact | · | body said plural 'state legislative assemblies and courts of accounts'; cited sources state singular instances of each | reworded to 'a state legislative assembly, a court of accounts' | |
| F4 hallucinated-fact | · | update record's fields[] named headline though the text is byte-identical before/after this run's edit | removed headline from fields[] | |
| F4 hallucinated-fact | · | (low confidence) epss value '1.09 (EUVD)' is out of the conventional 0-1 EPSS range and could not be independently re-verified this iteration (EUVD API 403/422) | epss set to null rather than propagate a physically-impossible figure | |
| F14 ? | · | (low confidence) 'Eleven distinct tools' is this run's own tally, not a source-stated count, and the body itself does not enumerate eleven named items | reworded to 'A purpose-built toolset' without asserting an unverifiable specific count | |
| F5 missing-citation | · | 'The current Langflow release is 1.12.0' carried no citation, and the entry's other source (BleepingComputer) states a different figure (1.11.6) for a different point in time | added the heise Security citation (the source stating 1.12.0 as current) | |
| F10 missed-angle | · | (low confidence) missed-angle duplicate of the F15 SynkLoader finding above | resolved by the F15 fix above |
Iteration #3 NEEDS_FIXES · 6 findings (truth=3, editorial=2, advisory=0) · Claude Sonnet 5 · 9m 20s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F4 hallucinated-fact | · | 'Scoping is unchanged for PaperCut Hive, PaperCut Pocket, Mobility Print and Print Deploy...'; the cited bulletin's own FAQ states only that Mobility Print and Print Deploy are unaffected; Hive and Po | removed the unsupported Hive/Pocket claim; sentence now names only Mobility Print and Print Deploy | |
| F4 hallucinated-fact | · | iteration 2's fix over-corrected 'courts of accounts' to singular; both cited sources state this specific item in the plural (a regression, not present before iteration 2) | reverted to 'state courts of accounts' (plural), keeping the other iteration-2 singular fix (federal ministry, national public agency, state legislative assembl | |
| F3 claim-not-supported | · | sources[].date '2026-06-30' for the OSV.dev/GHSA record matched neither OSV's own stated Published date (2026-07-22) nor NVD's REST API published date (2026-07-08), an 8-22 day drift | date corrected to 2026-07-22, matching OSV.dev's own stated Published date for the page actually cited | |
| F3 claim-not-supported | · | (low confidence) the past-end-of-life/support-period point was cited solely to Hogan Lovells Cadwalader, but that source's Art. 69(3) passage addresses only market-placement timing, not EOL/support-pe | split the citation in both the body and the Update section: Hogan Lovells for the market-placement-timing point, NCSC-FI (already cited elsewhere) added for the | |
| F14 ? | · | (low confidence) 'six weeks' between the 14 July patch and 30 August exploitation is a 47-day/6.7-week gap, closer to seven weeks | corrected 'six weeks' to 'nearly seven weeks' in title, summary and body (three instances) | |
| F16 ? | · | (low confidence) priority: high despite no confirmed exploitation and no CISA-KEV listing, inconsistent with this run's other non-exploited disclosure entries (MoiClient, Kimsuky, Gambling Goblin) all | downgraded to priority: notable for internal consistency with this run's other disclosure-only findings |
Iteration #4 NEEDS_FIXES · 3 findings (truth=2, editorial=1, advisory=0) · Claude Sonnet 5 · 8m 19s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | · | iteration 3's split-citation fix introduced an unsupported 'declared support period' phrase attributed to NCSC-FI in three places (body, Update section, Defender takeaway); NCSC-FI's page states only | reworded all three occurrences to match NCSC-FI's actual claim (EOL + no-longer-updated products remain subject to the obligation regardless), dropping the inve | |
| F14 ? | · | iteration 3's 'nearly seven weeks' fix landed in the summary and body but was missed in the title, which still read flat 'seven weeks' | title corrected to 'nearly seven weeks' | |
| F9 surface-contradiction | · | (low confidence) heise (1.12.0) and BleepingComputer (1.11.6, also cited) give different current/recommended-version figures with no surfaced resolution or Contradiction: note | added a clause noting 1.12.0 superseded 1.11.6 later the same day BleepingComputer's report was compiled, resolving the apparent conflict as a publish-timing ar |
Iteration #5 NEEDS_FIXES · 5 findings (truth=1, editorial=3, advisory=1) · Claude Sonnet 5 · 9m 49s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F4 hallucinated-fact | · | sourcing_note claimed only Goose's CVE carries a published CVSS score; the entry's own cited Hacker News source states OpenAI filed three CVEs of its own for a Codex helper in the same class, naming C | added CVE-2026-19592 to cves[] (CVSS 3.1 7.3), added a body sentence describing OpenAI's own three-CVE disclosure and quoting the mechanism for the named CVE, c | |
| F5 missing-citation | · | the (ZDI-26-034) identifier had no adjacent citation, the sentence's only link (ZDI-26-036) is for the sibling CVE | added a ZDI-26-034 sources[] record and an inline citation at that identifier | |
| F17 ? | · | (low confidence) classification.credibility: 1 treated BleepingComputer and heise as independent corroboration, but both restate the same single LinkedIn-only VulnCheck/Condon claim, one assessor, two | credibility corrected from 1 to 2 | |
| F16 ? | · | (low confidence, advisory) priority: high flagged as possibly under-calibrated given the zero-day/pre-auth/vendor-confirmed-exploitation profile reads close to the critical bar | declined, with rebuttal; see notes below | |
| F11 editorial-advisory | · | flagged 'sub-agent' and 'S3 finding' as workflow-internal language under the hard no-internal-language rule | declined, with rebuttal; see notes below |
Iteration #6 NEEDS_FIXES · 3 findings (truth=2, editorial=1, advisory=0) · Claude Sonnet 5 · 8m 23s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F4 hallucinated-fact | · | CVE-2026-19592's cves[].fixed said 'exact version not stated' though the entry's own cited Hacker News source gives '0.102.0 through 0.130.0, fixed in 0.131.0', independently confirmed via NVD | affected/fixed fields corrected to the stated version range and fix version | |
| F4 hallucinated-fact | · | 'superseded 1.11.6 ... later the same day' had no citation, neither cited source (heise, dated a full day after BleepingComputer) states the release timing | added a Langflow GitHub Releases sources[] record and inline citation for the release-timing claim | |
| F17 ? | · | classification.reliability: A for a GHSA advisory mirrored via OSV.dev contradicted sources.json's own github-advisory rating (B) and this store's own 2026-06-09 LiteLLM entry's rating of the identica | reliability corrected from A to B |
Iteration #7 NEEDS_FIXES · 3 findings (truth=1, editorial=2, advisory=0) · Claude Sonnet 5 · 12m 43s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | · | SimpleHelp/AnyDesk follow-on chain misattributed to the 'second wave'; the vendor bulletin's own changelog shows this IOC data was added 30 August ('Additional indicators of compromise'), two days bef | corrected the SimpleHelp/AnyDesk chain's attribution across all 4 locations (body, Update section, updates[].summary, actions[] item 2) to the first-days indica | |
| F9 surface-contradiction | · | (low confidence) NCSC-FI's own checklist still states a hard cap of two Assigned Representatives, contradicting ENISA's FAQ (1 Primary + up to 20 Secondary); entry silently followed ENISA's number wit | sourcing_note and body both revised to state both figures explicitly as an unreconciled discrepancy between the two authorities, rather than silently adopting E | |
| F17 ? | · | (low confidence) credibility 1 rested on one assessor (BerriAI's own advisory) for the vulnerability mechanism; CISA KEV corroborates only exploited-status, not the technical claim, same 'one assessor | credibility corrected from 1 to 2, sourcing_note added explaining the one-assessor basis |
Iteration #8 NEEDS_FIXES cap-breach · 3 findings (truth=2, editorial=0, advisory=1) · Claude Sonnet 5 · 12m 11s
| F-code | Section | Item · URL/quote | Verifier summary | Remediation · outcome |
|---|---|---|---|---|
| F3 claim-not-supported | · | 'only CVE-2026-19592 (CVSS 3.1 7.3) is named in the cited reporting [The Hacker News]' cites a source that states the opposite, HN's own text names only CVE-2026-72718's 7.0 as 'the only score any of | removed the unsupported '(CVSS 3.1 7.3)' parenthetical from the body sentence; the score remains correctly carried in the entry's structured cves[] frontmatter, | |
| F3 claim-not-supported | · | 'more sophisticated post-compromise behaviour than the first wave' invents a label the cited PaperCut bulletin never uses; the bulletin's own text reads 'than what was observed in the first days of th | quote-matched the body sentence to the bulletin's actual wording ('than what was observed in the first days of the incident'), removing the invented 'first wave | |
| F11 editorial-advisory | · | (low confidence, advisory) iterations 1 and 3's recorded truth/editorial counts don't match the code-classification of their own listed findings (iterations 2, 4-7 all check out exactly); pure audit-t | declined; historical per-iteration counts are recorded contemporaneously at each iteration and are not retroactively revised; the finding is noted here for the |
Verification & coverage notes
The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls: every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps, so nothing the run considered disappears silently.
Verification & coverage notesrun record body
2026-09-03T0410Z-intel · Sonnet 5 · window 26 h · 9 entries published
Verification & coverage notes
Runaway-duration warning (duration_seconds=11672, ~3.2 h): not a stall. The verification loop ran the full
8-iteration cap: seven consecutive NEEDS_FIXES verdicts, each with genuine truth/editorial findings requiring
remediation and a fresh cold re-spawn (per decision rules 3-4, F1/F4 or truth+editorial ≥ 3 on every iteration
through iteration 7), reaching the cap without a confirmed CLEAN. No sub-agent exceeded its per-role hard cap (45 min
research / 30 min verification) and none was abandoned; the total reflects nine new entries plus two changelog
updates across eight full verifier passes, not a hang.
Declined verifier findings (iteration 5), with rebuttal:
- F16 (SonicWall SMA1000 priority): the verifier flagged, at low confidence and explicitly advisory ("flagging for
the main agent to weigh, not asserting the calibration is wrong"), that
priority: highreads close to thecriticalbar given the zero-day/pre-auth/vendor-confirmed-exploitation profile. Declined: this store's existing 2026-07-14 SonicWall SMA1000 entry (CVE-2026-15409/15410) carries a near-identical profile, pre-auth SSRF chained to command injection, vendor-confirmed active exploitation, later ransomware-affiliate abuse, atpriority: high, notcritical. Upgrading this entry alone would create an unexplained inconsistency between two entries covering the same product line and vulnerability class three months apart;highis kept for consistency with that precedent rather than re-derived from the bar in isolation. - F11 (run-record language): the verifier flagged this section's use of "sub-agent" and "S3 finding" as workflow-
internal language under the hard no-internal-language rule. Declined: that rule's own text scopes explicitly to
entry fields, title, headline, summary, sourcing_note, body, changelog sections
(
prompts/cti-run.md§ Style rules), andtools/check_run.py's ownreader-text-internalscheck enforces it only against those entry fields, never against run records. The run record is the operational/audit artifact this same prompt section explicitly authorises to carry "phase names, gate/verifier mechanics", the S1-S4 sub-agent domain labels are load-bearing shorthand here, not a defect to scrub.
Declined verifier findings (iteration 8), with rebuttal:
- F11 (run-record historical tallies): the verifier flagged, at low confidence and explicitly advisory, that
iterations 1 and 3's recorded truth/editorial counts in
verification.iterations[]don't sum to match the code-classification of their own listed findings (iterations 2 and 4-7 all check out exactly). Declined: per-iteration counts are recorded contemporaneously at the time each iteration completes and are audit-trail history, not currently-published claims, no entry, published fact, or reader-facing content is affected. Retroactively rewriting already-committed iteration 1/3 counts risks introducing its own transcription error for zero reader-facing benefit; the discrepancy is noted here transparently instead.
Coverage window: Standard (gap_hours 24.0, window_hours 26, no catch-up/major-gap disclosure required).
KEV mechanical sweep (v4.8 duty): tools/kev_window_diff.py --window-hours 26 found 7 in-window CISA KEV additions,
3 already covered (CVE-2026-82329 JFrog, CVE-2026-48710 Starlette, CVE-2026-49869 Kestra, logged, no action) and 4
NOT COVERED. All 4 received a disposition this run: CVE-2026-59822 (BerriAI LiteLLM), CVE-2026-83548/CVE-2026-83549
(SonicWall SMA1000) and CVE-2026-9586 (Sangoma Switchvox) each published as a new entry. No borderline-drops from
this set.
Single-source items (standard, no carve-out): MoiClient (AhnLab ASEC only); Kimsuky Backblaze-B2 LNK campaign (AhnLab ASEC only); Teams helpdesk-impersonation/EtherRatz campaign (Microsoft only, no independent write-up of this specific 2026-09-02 publication located).
Reduced-confidence inclusion (PD-12): CVE-2026-0768 (Langflow renewed exploitation), both sources
(BleepingComputer, heise) are news-aggregator hosts; VulnCheck's own commentary is LinkedIn-only and not citable as
a URL. Included with reduced confidence (confidence: medium) per PD-12 rather than dropped, since the underlying
CVE identity, exploitation timeline and technical detail are independently confirmed by NVD/ZDI/GitHub-Releases
cross-checks in the Phase 2 spot-check.
Borderline drops:
- UK Supreme Court Shehabi v. Bahrain spyware-immunity ruling (S3 finding, flagged borderline by the sub-agent itself), no technical/TTP content for a highly technical SOC audience, no Swiss/EU nexus stated in any source; a foreign-jurisdiction legal precedent that does not change what a Tier 2/3 responder does in the next 7 days.
- Silver Fox counterfeit-installer brand-impersonation campaign (S3 finding), victims overwhelmingly China-based operations and Chinese-speaking users; the one transferable technique (server-side per-request hash regeneration defeating hash-based blocklisting) does not add a materially new detection concept beyond this store's existing malware-distribution coverage, and the campaign carries no home-region, coverage-focus or profiled-sector nexus.
Coverage backlog (state/coverage_backlog.md): two new open rows, suspected IDScan.net/Nexus driver's-license
marketplace breach (153M+ documents, US/Canada; no source states an access vector or mechanism, so no incident
entry can carry an evidence-bound ATT&CK mapping, same blocking condition as the standing Boston Scientific row);
Kairos extortion group's claim against Ville de Libercourt, France (bare leak-site listing, no victim confirmation).
Six existing open rows re-checked with dated notes, all "no change": the Zurich LockerGoga/MegaCortex/Nefilim
verdict (not due until 2026-09-10), the Siemens S7 PDF re-read, CVE-2026-16242 (Red Hat OpenShift), the Boston
Scientific incident, Ixa Systems SA/TheGentlemen, and UICC/Krybit. The inside-it.ch/Insel Gruppe row was re-checked
and hit a new failure mode (whole-host HTTP 429, distinct from the prior paywall/403 conditions) rather than a
resolution.
Coverage gaps: inside-it-ch (whole-host HTTP 429 on every transport this run, blocked both the Insel Gruppe
backlog re-check and an unrelated Swiss Federal Council post-quantum-cryptography roadmap lead); ssd-disclosure
(anti-bot interstitial on the listing page again; 4th+ consecutive affected run, though this run's own
source_health.py sweep classed the host reachable, so the block is specific to the listing page's content shape,
not the whole host).
Entity/relation notes: actor:earth-berberoka (alias Gambling Goblin) registered with typed uses relations to
tool:orat, tool:alphaagent and tool:downpro. malware:etherrat (existing entity) is referenced, not
re-registered, on the Teams helpdesk-impersonation entry, Microsoft's own article never uses the "EtherRAT" name
(its Defender detection signatures read "EtherRatz"), so the entry's references[] and sourcing_note record this as
a mechanistic overlap the entry asserts, not an identity Microsoft itself states.
Deep dive: 2026-09-03/gambling-goblin-earth-berberoka-gov-apache-seo-fraud, selected under criterion 3
(substantive new technical analysis with actionable detection guidance); category other (post-compromise
government-web-server implant/SEO-fraud infrastructure abuse, not a classic espionage APT campaign nor any existing
rotation category). No deep dive published in the preceding 24 h window at run start.
← Operations dashboard · day page 2026-09-03 · run-record contract: docs/pipeline.md